Wi-Fi Publik dan Sebuah Panggilan Telepon, Bagaimana Mereka Menjadi Perangkap Sempurna untuk Mencuri Aset Kripto Senilai $5000?

比推Published on 2026-01-09Last updated on 2026-01-09

Abstract

Penulis kehilangan aset kripto senilai $5000 setelah menggunakan Wi-Fi publik di hotel selama liburan. Meskipun tidak mengklik tautan phishing atau menandatangani transaksi mencurigakan, dompet kriptonya dikuras. Investigasi mengungkapkan serangan "man-in-the-middle" melalui jaringan Wi-Fi hotel yang tidak aman. Kesalahan utamanya: 1. Berbicara tentang kripto di area publik, membuatnya menjadi target 2. Menyetujui permintaan otorisasi tanpa verifikasi saat menggunakan Jupiter Exchange 3. Tidak menggunakan hotspot pribadi alih-alih Wi-Fi publik Peretas menyuntikkan kode jahat yang menggantikan permintaan transaksi legit, membuat korban memberikan akses ke dompetnya. Setelah korban meninggalkan hotel, peretas mentransfer semua aset termasuk SOL dan NFT. Meski bukan dompet utama, insiden ini menekankan pentingnya keamanan jaringan, kerahasiaan informasi, dan verifikasi ekstra untuk setiap permintaan tanda tangan dompet kripto.

Penulis: The Smart Ape

Disusun oleh: Deep Tide TechFlow

Judul Asli: Terhubung ke Wi-Fi Hotel selama Tiga Hari, Dompet Kripto Digerogoti $5000


Beberapa hari yang lalu, saya dan keluarga pergi ke sebuah hotel yang sangat bagus untuk menghabiskan liburan akhir tahun. Sehari setelah meninggalkan hotel, dompet saya ternyata benar-benar dikosongkan. Saya bingung, karena saya tidak mengklik tautan phishing apa pun, juga tidak menandatangani transaksi jahat apa pun.

Setelah berjam-jam menyelidiki dan meminta bantuan ahli, akhirnya saya memahami kebenarannya. Ternyata semua ini terjadi karena jaringan Wi-Fi hotel, sebuah panggilan telepon singkat, dan serangkaian kesalahan bodoh.

Seperti kebanyakan penggemar kripto, saya membawa laptop, berpikir bisa menyempatkan bekerja sambil menemani keluarga berlibur. Istri saya terus bersikeras agar saya tidak bekerja selama tiga hari ini, seharusnya saya mendengarkannya.

Seperti tamu lainnya, saya terhubung ke jaringan Wi-Fi hotel. Jaringan ini tidak memerlukan kata sandi, hanya perlu login melalui halaman verifikasi (captive portal).

Saya bekerja seperti biasa di hotel, tidak melakukan operasi berisiko: tidak membuat dompet baru, tidak mengklik tautan aneh, juga tidak mengakses aplikasi terdesentralisasi (dApps) yang mencurigakan. Saya hanya melihat X (Twitter), saldo saya, Discord, dan Telegram, dll.

Pada suatu saat, saya menerima panggilan dari seorang teman di dunia kripto, kami berbicara tentang kondisi pasar, Bitcoin, dan topik terkait kripto. Namun yang tidak saya ketahui, ada seseorang di dekat sana yang menguping percakapan kami, dan menyadari bahwa saya berkecimpung dalam hal-hal terkait kripto. Ini adalah kesalahan pertama saya. Dari percakapan kami, pihak lawan mengetahui bahwa saya menggunakan dompet Phantom, dan bahwa saya adalah pengguna dengan jumlah holding yang cukup besar.

Ini membuatnya menjadikan saya sebagai target.

Dalam jaringan Wi-Fi publik, semua perangkat berbagi jaringan yang sama, sebenarnya visibilitas antar perangkat lebih tinggi dari yang Anda bayangkan. Hampir tidak ada langkah perlindungan nyata antar pengguna, ini membuka peluang untuk "Serangan Man-in-the-Middle" (Serangan Orang di Tengah). Penyerang bertindak seperti orang tengah, diam-diam menyelip di antara Anda dan internet, seperti seseorang yang diam-diam membaca dan memanipulasi surat Anda sebelum sampai.

Ketika saya menjelajah di Wi-Fi hotel, ada sebuah situs web yang terlihat loading normal, tetapi sebenarnya di balik halaman disuntikkan kode jahat tambahan. Saat itu saya tidak menyadari adanya keanehan. Jika saya menginstal beberapa alat keamanan, seharusnya bisa menemukan masalah ini, tetapi sayangnya, saya tidak memilikinya.

Biasanya, situs web mungkin meminta dompet Anda untuk menandatangani operasi tertentu. Dompet Phantom akan memunculkan jendela pop-up, Anda dapat memilih untuk menyetujui atau menolak. Umumnya, Anda akan dengan percaya diri menandatangani karena mempercayai situs web dan browser ini. Namun, hari itu saya tidak seharusnya melakukannya.

Persis ketika saya sedang melakukan operasi pertukaran token di platform @JupiterExchange, kode jahat memicu permintaan dompet, menggantikan operasi pertukaran normal saya. Saya seharusnya bisa menemukan bahwa ini adalah permintaan jahat dengan memeriksa detail transaksi dengan cermat, tetapi karena saya sudah dalam operasi pertukaran di platform Jupiter, saya sama sekali tidak curiga.

Hari itu saya tidak menandatangani transaksi yang mentransfer dana, tetapi menandatangani sebuah otorisasi. Inilah yang menyebabkan aset dicuri beberapa hari kemudian.

Kode jahat tidak langsung meminta saya untuk mengirim SOL (Solana), karena itu akan terlalu jelas. Sebagai gantinya, ia meminta saya "mengizinkan akses", "menyetujui akun", atau "mengonfirmasi sesi". Dengan kata sederhana, saya sebenarnya memberikan izin kepada alamat lain untuk beroperasi atas nama saya.

Alasan saya menyetujuinya adalah karena saya salah mengira ini terkait dengan operasi saya di Jupiter. Saat itu, informasi yang muncul di pop-up dompet Phantom terlihat sangat teknis, tidak menampilkan jumlah apa pun, juga tidak提示 transfer segera.

Dan inilah semua yang dibutuhkan penyerang. Dia menunggu dengan sabar, sampai saya meninggalkan hotel, baru mulai bertindak. Dia mentransfer SOL saya, mengambil token saya, dan memindahkan NFT saya ke alamat lain.

Saya tidak pernah membayangkan hal seperti ini bisa terjadi pada saya. Untungnya, ini bukan dompet utama saya, tetapi dompet panas untuk operasi tertentu, bukan untuk menyimpan aset jangka panjang. Meskipun begitu, saya membuat banyak kesalahan, dan saya merasa bertanggung jawab utama atas hal ini.

Pertama, saya seharusnya tidak pernah terhubung ke Wi-Fi publik hotel. Saya seharusnya menggunakan hotspot ponsel untuk internet.

Kesalahan kedua saya adalah, membicarakan kripto di area publik hotel, membuat banyak orang mungkin mendengar percakapan kami. Ayah saya pernah menasihati, jangan pernah membiarkan orang lain tahu Anda berkecimpung dalam hal terkait kripto. Kali ini masih beruntung, beberapa orang bahkan mengalami penculikan atau hal yang lebih buruk karena aset kripto.

Kesalahan lain adalah, saya menyetujui permintaan dompet tanpa sepenuhnya memperhatikan. Karena saya yakin permintaan ini berasal dari Jupiter, saya tidak menganalisisnya dengan cermat. Faktanya, setiap permintaan dompet harus ditinjau dengan serius, bahkan di aplikasi yang Anda percayai. Permintaan bisa disadap, sebenarnya bukan berasal dari aplikasi yang Anda kira.

Pada akhirnya, saya kehilangan sekitar $5000 dari sebuah dompet sekunder. Meskipun ini bukan situasi terburuk, tetap sangat membuat frustrasi.


Twitter:https://twitter.com/BitpushNewsCN

Grup Komunikasi Telegram比推:https://t.me/BitPushCommunity

Langganan Telegram比推: https://t.me/bitpush

Tautan asli:https://www.bitpush.news/articles/7601380

Related Questions

QApa yang menyebabkan penulis kehilangan aset kriptonya senilai $5000?

APenulis kehilangan aset karena kombinasi dari penggunaan Wi-Fi publik hotel, percakapan telepon yang terdengar oleh penyerang tentang aktivitas kriptonya, dan persetujuan tidak sengaja terhadap permintaan otorisasi jahat yang disuntikkan melalui serangan man-in-the-middle.

QApa itu serangan 'man-in-the-middle' yang disebut dalam artikel?

ASerangan man-in-the-middle adalah ketika penyerang menyisipkan diri di antara perangkat korban dan internet di jaringan yang sama (seperti Wi-Fi publik), memungkinkan mereka mengintip dan memanipulasi data yang dikirim, seperti menyuntikkan kode jahat ke situs web yang dikunjungi.

QKesalahan apa saja yang diakui penulis sebagai penyebab insiden ini?

APenulis mengakui tiga kesalahan utama: 1) Menggunakan Wi-Fi publik hotel alih-alih hotspot pribadi, 2) Membicarakan aktivitas kripto di area publik sehingga didengar orang lain, 3) Tidak memeriksa dengan cermat permintaan persetujuan dompet yang ternyata jahat.

QMengapa penyerang tidak langsung mencuri aset saat penulis masih di hotel?

APenyerang meminta otorisasi akses, bukan transfer langsung, sehingga tidak mencurigai. Mereka kemudian menunggu dengan sabar sampai penulis meninggalkan hotel untuk benar-benar mengambil aset, mengurangi risiko ketahuan.

QApa pelajaran utama yang bisa diambil dari pengalaman penulis?

APelajaran utamanya adalah selalu hindari Wi-Fi publik untuk aktivitas sensitif seperti kripto, gunakan hotspot pribadi; jangan bicarakan hal sensitif di tempat umum; dan selalu periksa secara detail setiap permintaan persetujuan dompet, bahkan dari aplikasi tepercaya.

Related Reads

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

The article analyzes the three leading Chinese optical module companies, collectively nicknamed "Yi Zhong Tian": Xinyisheng, Zhongji Innolight, and TFC Optical Communication. It evaluates their "cost-performance" not by current stock price, but through three lenses: PEG ratio (growth vs. valuation), earnings quality, and premium/discount for certainty. Xinyisheng shows the most attractive PEG ratio and high profitability, but its valuation reflects discounts for risks like high customer concentration and reliance on overseas markets. Zhongji Innolight, the most expensive, commands a premium for its market leadership, dominant share in key products like 800G/1.6T modules, and higher earnings certainty, though it faces geopolitical risks. TFC Optical, as an upstream component supplier ("water seller"), has the highest gross margin and bets on the long-term CPO/NPO architecture trend, but trades at a high valuation with more stable, less explosive growth. The core argument is that while these companies dominate module assembly, the true profit pool and technological moat lie upstream in laser and switch chips, currently controlled by U.S. firms like Lumentum and Coherent. The long-term "cost-performance" for these Chinese leaders hinges on whether the domestic industry, exemplified by companies like Yuanjie Technology, can successfully move up the value chain into high-power laser chips. Otherwise, their high growth may remain confined to the lower-margin assembly segment.

marsbit5m ago

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

marsbit5m ago

Has the Crypto Market Bottomed? Here's What Institutions Think

The crypto market is in a period of significant debate, with leading institutions offering differing views on whether a bottom has been reached. Three prominent firms have published detailed analyses: * **Galaxy Digital** argues Bitcoin has **not yet bottomed**. Their analysis of 13 historical indicators across six dimensions (valuation, profit-taking, miner pressure, etc.) shows only four are fully met. They project a potential bottom range between $30k and $54k. * **NYDIG** states a bottom is **possible but not likely**. While metrics are close to historic bear market extremes, they note the absence of a classic panic-selling event. They also suggest increased institutional adoption may have structurally altered the market cycle, potentially leading to a shallower downturn. * **Standard Chartered Bank** asserts the **bottom has already occurred** at around $59k. They cite two key factors: potential US-Iran diplomatic progress and the anticipated SpaceX IPO, which they believe absorbed capital and caused ETF selling pressure that is now subsiding. They forecast a year-end price target of $100k. Despite the surface-level disagreement, the reports share critical common ground more valuable for long-term investors: 1. All three believe the market bottom will form **within this year**. 2. All agree the current price is **closer to the bottom than to previous highs**. 3. All maintain a **bullish long-term outlook** for Bitcoin and a new cycle. The core takeaway is that while the exact bottom price ($40k, $50k, or $60k) is debated, the consensus is that a bottom is imminent. For long-term holders, the primary focus should not be pinpointing the absolute low, but on the future potential for prices to reach $100k, $200k, or higher. The fundamental thesis for Bitcoin—sovereign debt accumulation, inflation, declining trust in centralized institutions, global digitization, and improved accessibility—remains intact and is arguably strengthening. The overall landscape is viewed as more favorable than in previous crypto winters.

marsbit16m ago

Has the Crypto Market Bottomed? Here's What Institutions Think

marsbit16m ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

China's Photonics Industry: Bottlenecks and Breakthroughs In the global AI race, computing chips dominate the narrative, but the underlying bottleneck increasingly defining the scale of AI clusters is light—or more specifically, optical connectivity. Optical modules, which translate electrical signals to light and vice versa, are crucial for connecting thousands of GPUs in AI data centers, preventing data congestion and ensuring efficient model training. High-speed modules (800G, 1.6T) are now standard, with performance hinging on advanced DSP (Digital Signal Processor) chips. This is where a critical dependency lies. Two US giants—Marvell and Broadcom—collectively dominate over 90% of the high-end DSP chip market. Chinese optical module leaders like Zhongji Innolight and Eoptolink rely on these chips to manufacture modules for overseas AI customers, primarily in North America. While this creates a supply chain vulnerability, complete decoupling is difficult. Marvell derives over half its revenue from Greater China, and the US firms depend on Chinese partners for chip packaging and optical components. The risk from laser chips (e.g., from Lumentum), another key component, is considered more manageable due to multiple global suppliers and faster progress in domestic alternatives from companies like YOFC and Accelink. To mitigate risks, China's industry is pursuing a multi-pronged strategy: diversifying supply chains and locking in long-term orders; fostering a domestic market ecosystem to adopt homegrown DSPs from firms like Huawei HiSilicon and CETC; accelerating R&D in high-speed DSPs and advanced packaging; and investing in next-gen technologies like silicon photonics and Co-Packaged Optics (CPO) to reduce reliance on discrete DSPs. The ultimate solution lies not in short-term博弈 but in persistent advancement of domestic high-end chip R&D and manufacturing. While challenges remain in performance, certification, and ecosystem building, China's vast domestic market and manufacturing base provide a crucial buffer, buying time for the industry to achieve greater technological independence.

marsbit29m ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

marsbit29m ago

Behind SpaceX's $2 Trillion Market Cap: Why Does Musk Always Have the Next Move Planned?

On June 12th, SpaceX debuted on the Nasdaq, reaching a valuation that briefly touched $2 trillion. This marked the culmination of a 24-year journey from its founding in 2002, driven by Elon Musk's frustration at the high cost of buying rockets. The company's path was defined by early failures, with its first three Falcon 1 launches ending in explosions before a successful 2008 flight opened the era of commercial spaceflight. Key to its model was a fixed-price NASA contract, incentivizing cost reduction. SpaceX mastered rocket reusability, first achieving a Falcon 9 landing in 2015, which drastically cut launch costs. This enabled its profitable Starlink satellite internet constellation, envisioned years before reusability was proven, to create an internal market for frequent launches. Similarly, the next-generation Starship rocket was in development long before its first flight, with its business case evolving from Mars colonization to supporting the emerging concept of in-orbit data centers for AI—a story now central to its valuation. The company's recent IPO, a reversal of its long-standing "no IPO" stance, is funding this ambitious "space-based compute" vision. While major tech players like Google, Blue Origin, and others are investing heavily, significant technical and cost hurdles remain. Ultimately, SpaceX's history is one of creating its own demand: first with Starlink and now with space-based AI compute, betting that its next rocket will enable its next giant market.

marsbit32m ago

Behind SpaceX's $2 Trillion Market Cap: Why Does Musk Always Have the Next Move Planned?

marsbit32m ago

Trading

Spot
Futures

Hot Articles

How to Buy APE

Welcome to HTX.com! We've made purchasing ApeCoin (APE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy ApeCoin (APE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your ApeCoin (APE)After purchasing your ApeCoin (APE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade ApeCoin (APE)Easily trade ApeCoin (APE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

3.9k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy APE

What is APECOIN

Understanding Asia Pacific Electronic Coin ($APECoin) In an era where the intersection of technology and environmentalism is becoming increasingly critical, cryptocurrencies are making their mark as potential catalysts for change. Among these innovations, Asia Pacific Electronic Coin ($APECoin) stands out as a distinct project designed to support environmental initiatives across the Asia Pacific region. This article delves into the foundation, unique features, and impact of $APECoin within the broader blockchain landscape. What is Asia Pacific Electronic Coin ($APECoin)? Asia Pacific Electronic Coin ($APECoin) is an ERC20 and TRC20 token, brought to fruition in April 2020 after its conceptualization in December 2019. This innovation was born out of a desire to foster eco-friendly practices and support a suite of environmental projects aimed at sustainability and green initiatives. Aims and Objectives $APECoin is not merely a digital currency; it is envisioned as a medium of exchange that enables users to engage in transactions that directly benefit environmental causes. Its ecosystem is designed to facilitate various financial activities while promoting the adoption of eco-friendly practices. The currency aims primarily to: Support Environmental Initiatives: Through every transaction, a portion is allocated to funding sustainable projects aimed at conservation and renewable energy. Promote Eco-Friendly Innovations: Encouraging startups and projects that align with environmental sustainability through the use of its token as a means of value. Create a Sustainable Marketplace: The platform includes an e-marketplace where financial transactions can occur within a framework dedicated to promoting green practices. Creator of Asia Pacific Electronic Coin ($APECoin) While the details regarding the individual creator of $APECoin are not publicly disclosed, the project is significantly backed by the APEC Group, a consortium focused on advocating for environmental initiatives. This backing adds credibility and significance to the project, connecting it to a broader network committed to sustainability and eco-friendly practices. Investors of Asia Pacific Electronic Coin ($APECoin) The investment landscape surrounding $APECoin remains largely undisclosed. Specific names of investment foundations or organizations supporting this cryptocurrency have yet to be revealed. However, what is evident is a growing interest among investors keen on supporting sustainable projects that demonstrate potential for impact in the crypto space. How does Asia Pacific Electronic Coin ($APECoin) work? $APECoin stands out due to its innovative operational model, which leverages blockchain technology and smart contracts. This combination not only ensures transactional efficiency but also enforces adherence to regulatory frameworks, enhancing the security and transparency of transactions. Unique Features of $APECoin Blockchain-Based Operations: By establishing its operations on a blockchain platform, $APECoin ensures that all transactions are immutable and secured through advanced cryptographic techniques. This decentralization underscores the integrity of the token within its ecosystem. Smart Contracts: $APECoin employs smart contracts that facilitate seamless transactions while ensuring compliance with applicable regulations. These automated agreements minimize the possibility of disputes, streamline processes, and contribute to a reliable transaction framework. E-Marketplace: One of the hallmark features of $APECoin is its dedicated e-marketplace. This digital environment serves as a hub for services that endorse eco-friendly practices, providing a platform for exchanges that further the project's green vision. Through these attributes, $APECoin carves a niche for itself within the vast expanse of the cryptocurrency market, effectively marrying the principles of blockchain with environmental stewardship. Timeline of Asia Pacific Electronic Coin ($APECoin) Understanding the trajectory of $APECoin provides insight into its developmental milestones and future aspirations. Here’s a timeline highlighting significant events in the project’s history: December 2019: Conceptualization of Asia Pacific Electronic Coin, initiated with an ambition to drive sustainability through cryptocurrency. April 2020: Official launch of $APECoin, marking its entry into the marketplace as a dedicated token for environmental projects. 2020-2021: Conducting of the Initial Exchange Offering (IEO), enabling users to purchase $APECoin, alongside the registration with various electronic exchange platforms to enhance accessibility. In its relatively short journey, $APECoin has made significant strides in laying the groundwork for a secure and impactful cryptocurrency driven by environmental goals. Conclusion Asia Pacific Electronic Coin ($APECoin) embodies the marriage of technology and environmental responsibility, fostering growth in the crypto ecosystem while championing sustainability. With its unique structure, backing by reputable entities, and vision for a greener future, $APECoin is more than just a cryptocurrency; it is a pioneering project aimed at nurturing responsible innovation in the Asia Pacific region. Through its commitment to financial inclusion and its support of environmental initiatives, it stands as a formidable example of how digital currencies can be leveraged for positive societal impact. As the project continues to evolve, stakeholders within the crypto community and beyond will be eagerly watching how $APECoin shapes the conversation around sustainable practices in the burgeoning world of cryptocurrency.

890 Total ViewsPublished 2024.12.03Updated 2024.12.03

What is APECOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of APE (APE) are presented below.

活动图片